Summary
Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.
Take Action:
If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)